logo

Critical Cisco ISE Vulnerabilities Allow Remote Command Execution

ID: f8973b7f-2d87-5511-8e78-8fa4eb7d87ac

STIX ID: report--f8973b7f-2d87-5511-8e78-8fa4eb7d87ac

Feed Name: ThreatCluster

Threat Score
70/100

Date Published: 2026-06-18

Date Updated: 2026-06-22

...
...

Cisco disclosed two serious vulnerabilities in Identity Services Engine (CVE-2026-20181 and CVE-2026-20190). CVE-2026-20181 (CVSS 9.1) can allow authenticated administrators to send crafted HTTP requests and potentially escalate to root; CVE-2026-20190 (CVSS 7.5) can allow unauthenticated access to sensitive information such as hashed credentials. Cisco has published patches and urges immediate updating; ISE-PIC has reached end-of-sale and no active exploitation has been reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.